Configure which Confluence groups can access pages at each classification level.
Navigate to Confluence Settings → Classification Levels Management → Level Permissions tab

How it works: When you assign groups to a classification level, the app automatically applies Confluence page restrictions to all pages with that classification.
For each classification level, you can configure two types of access:
- Edit Groups – Can edit and modify pages
- Full access to page content
- Can change classification levels
- Can edit page properties
- View Groups – Read-only access
- Can view page content
- Cannot edit or modify
- Cannot change classification
Steps:
- Select a classification level from the dropdown
- In the Edit Groups field, type and select Confluence groups
- In the View Groups field, type and select Confluence groups
- Click Save to apply the permissions
- The app will automatically update page restrictions for all pages with that classification level
Important Notes:
- Groups must exist in Confluence before you can assign them
- Changes apply immediately to all pages with that classification
- Previous manual restrictions on pages may be overridden
- Users need to be members of the specified groups to access classified pages
Best Practice:
- Create dedicated groups for each classification level (e.g.,
secret-edit,secret-view) - Use descriptive group names that clearly indicate their purpose
- Regularly audit group memberships to ensure appropriate access
- Test permission changes with different user accounts
New: choose whether classification levels control page restrictions
A new setting, “Apply page restrictions from classification levels”, is available in Classification Levels Management → Level Permissions.
- On (default): classification levels control page restrictions. A level’s edit and view groups replace the page’s restrictions, and a level with no groups removes them, so a page’s classification always matches who can access it.
- Off: classification only labels pages. Existing page restrictions are never changed.
Improved: consistent restrictions everywhere
Single pages, page trees, Save & Apply and large background jobs now all apply the same rule. Import Page Metadata applies restrictions only for levels that have groups, and never removes existing restrictions.
New: confirmations before restrictions are removed
- Classifying a page tree with a level that has no groups shows a warning with the number of pages affected.
- Save & Apply on a level with no groups asks for confirmation and shows how many pages will lose their restrictions.
Improved: clearer results
- If Confluence doesn’t allow a restriction change, the page is still classified and a warning explains why. Page restrictions require a paid Confluence plan.
- Save & Apply now reports how many pages were updated and how many were not.